There is a category of business task that never becomes urgent until the day it becomes very urgent indeed, and data protection sits at the top of it. Nobody has ever lost a night's sleep over an unwritten privacy notice. Plenty of owners have lost a week over an email from a former employee asking for everything the company holds about them, or a client asking, in the middle of a contract negotiation, where their customer data is actually stored.
The reason it gets deferred is that the subject arrived dressed as a compliance project. In 2018 small businesses were sold consultancy days, sixty-page policy packs and impact assessments for processing that amounted to a mailing list and a shelf of invoices. Most of that was theatre, and quietly ignoring it was a rational response.
What is not theatre is the small set of obligations that a five-person business genuinely has, and that a regulator, a client's procurement team or a disgruntled ex-employee can actually test. That set is short enough to clear in an afternoon.
Hour one: write down what you hold
Start with the only document that makes the rest possible. Not a policy — a list.
Go through it by category. Customer names, addresses, emails and order history in your accounting software. Employee records: contracts, bank details, next of kin, absence and sickness notes, right-to-work copies. Job applicant CVs, including the ones from the vacancy you filled last year. Marketing contacts in your email platform. CCTV, if you have it. Website analytics and any tracking pixels. Supplier contacts. WhatsApp groups with staff. The shared drive, which will contain things nobody remembers putting there.
For each one, note four things: what it is, why you hold it, where it lives, and how long you keep it. That list is the backbone of everything else. It also tends to answer the question of whether you needed any of it in the first place, which is usually where the quickest wins are.
Almost every small business data problem is really a hoarding problem. You cannot lose control of information you deleted three years ago.
Hour two: pay the fee and check the exemption
Most UK businesses that process personal data electronically must pay the data protection fee to the Information Commissioner's Office. It is a statutory annual fee, not a subscription, and it is unrelated to how good your compliance is.
The tiers are straightforward. Tier 1 is £52 a year for organisations with a maximum turnover of £632,000 or no more than 10 staff. Tier 2 is £78 for up to £36 million turnover or no more than 250 staff. Tier 3, for everyone above that, is £3,763. Some small organisations are genuinely exempt — the ICO publishes a self-assessment tool that settles it in a few minutes — but the exemptions are narrower than people hope, and payroll processing alone usually brings you in.
For the cost of one hour of a consultant's time you have removed the single most easily checked failing on the list. It is also the thing a client's procurement questionnaire asks about first, because it is the one answer that can be verified from a public register.
Hour three: the four documents that do the work
A privacy notice on your website. Plain English, one page. What you collect, why, who you share it with, how long you keep it, and how someone exercises their rights. It does not need legal drafting; it needs to be true and to match the list you made in hour one.
An employee privacy notice. Separate from the customer one, because you hold far more about staff than about customers and for far longer. Issue it with the contract.
A retention schedule. Three lines per category is enough. Accounting records six years, because tax law requires it. Recruitment records for unsuccessful applicants six to twelve months, then deleted. Marketing contacts reviewed annually. This is the document that turns hoarding into a policy rather than an accident.
A one-page breach procedure. Who is told, in what order, and the fact that a reportable breach must reach the ICO within 72 hours of you becoming aware of it. Write it now, because the day you need it is the day nobody can think straight.
Hour four: the practical controls that actually prevent incidents
Documents are not what stops a breach. Habits are. Turn on two-factor authentication everywhere, particularly on email and the accounting system. Remove access for people who left — the leaver checklist is the single most commonly skipped control in a small business, and an ex-employee with live access to a shared inbox is both a data breach and an employment problem waiting to happen.
Stop emailing spreadsheets of personal data around. Use shared links with expiry instead. Check where your data physically sits with your main suppliers, and get their data processing terms on file: your accounting software, CRM, email platform and cloud storage are all processing personal data on your behalf, and if a client asks who your processors are, that list is the answer.
The everyday risk is not a hacker. It is a laptop left on a train, an email to the wrong recipient, or a bcc field used as a cc — that last one being the most common self-inflicted breach in British small business.
Where this stops being a compliance chore
Two things make this worth the afternoon. The first is that data questions have quietly moved into commercial contracts: any decent-sized client, and every public-sector buyer, now asks about ICO registration, sub-processors and breach procedures before signing. Answering in a day rather than a fortnight is a competitive advantage in the same way that having your contracts in order is.
The second is subject access requests. Any individual — a customer, an applicant, an employee, an ex-employee mid-dispute — can ask for everything you hold about them, and you generally have one month to provide it. If you know what you hold and where, that is a morning's work. If you do not, it is a fortnight of panic through six years of email at exactly the moment you can least afford it. That is the real reason to spend the four hours, and it has nothing to do with fines.
Common questions
Do small businesses in the UK have to register with the ICO?
Most do. If you process personal data electronically you are generally required to pay the annual data protection fee unless a specific exemption applies. Tier 1 is £52 a year for organisations with turnover up to £632,000 or no more than 10 staff, tier 2 is £78, and tier 3 is £3,763. Exemptions exist for some limited processing — certain not-for-profit activity, staff administration in narrow circumstances, and purely personal or household use — but running payroll, keeping customer records or doing email marketing normally brings you within scope. The ICO's online self-assessment tool gives a definitive answer in a few minutes.
What counts as a data breach I have to report?
A personal data breach is any security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. You must report it to the ICO within 72 hours of becoming aware of it where it is likely to result in a risk to people's rights and freedoms, and you must tell the affected individuals as well where that risk is high. Not every incident qualifies: a mistyped email to a colleague usually does not, while a customer list sent to the wrong company or a stolen unencrypted laptop usually does. Record every incident and your reasoning, even the ones you decide not to report.
How long do I have to respond to a subject access request?
One month from receipt, and you cannot charge for it in ordinary cases. The deadline can be extended by a further two months where the request is genuinely complex or where someone has made several requests, but you must tell the individual about the extension within the first month. A request does not have to use any particular wording or mention data protection to be valid — an email asking what you hold about them counts, whoever it is sent to. This is precisely why a written record of what data you hold and where it lives is worth building before you receive one rather than after.
Do I need consent to email my customers?
Not always. UK direct marketing rules distinguish between consent and the soft opt-in: where you obtained someone's details in the course of a sale or negotiations for a sale of your own similar products or services, gave them a clear chance to opt out at that point, and give them an unsubscribe option in every message, you can generally market to them without separate consent. Cold B2C email needs consent. Business-to-business email to corporate addresses is treated more permissively, though the right to object still applies. In all cases keep a record of where each contact came from and when.


